Bug #73173 [NEW]: huge memleak when wddx_unserialize
| From: | tloi at fortinet dot com | Date: | Mon, 26 Sep 2016 08:13:09 +0000 |
| Subject: | Bug #73173 [NEW]: huge memleak when wddx_unserialize | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-204269@lists.php.net to get a copy of this message | ||
From: tloi at fortinet dot com
Operating system: All
PHP version: master-Git-2016-09-26 (Git)
Package: WDDX related
Bug Type: Bug
Bug description:huge memleak when wddx_unserialize
Description:
------------
If the xml document has <var name="xxx"> tag without </var>, the varname
variable will never freed and causing memory leak equal to the
strlen(varname).
<snippet func php_wddx_push_element>
} else if (!strcmp((char *)name, EL_VAR)) {
int i;
if (atts) for (i = 0; atts[i]; i++) {
if (!strcmp((char *)atts[i], EL_NAME) && atts[i+1] && atts[i+1][0])
{
if (stack->varname) efree(stack->varname);
stack->varname = estrdup((char *)atts[i+1]); //strdup the varname
break;
}
}
} else if (!strcmp((char *)name, EL_RECORDSET)) {
</snippet>
Patch is simple, free the varname when destroy the stack:
--- a/ext/wddx/wddx.c
+++ b/ext/wddx/wddx.c
@@ -241,6 +241,9 @@ static int wddx_stack_destroy(wddx_stack *stack)
}
efree(stack->elements);
}
+ if (stack->varname) {
+ efree(stack->varname);
+ }
return SUCCESS;
}
/* }}} */
This bug may lead to DoS on the server as the leak is significant for
each request, the poc is leaking 8MB of memory without any special
configuration.
compiled with only --enable-debug --enable-wddx
Test script:
---------------
<?php
$xml=<<<XML
<?xml version='1.0'?>
<!DOCTYPE wddxPacket SYSTEM 'wddx_0100.dtd'>
<wddxPacket>
<var name="
XML;
$xml .= str_repeat('F',0x800000);
$xml .= <<<XML
">
</wddxPacket>
XML;
var_dump(wddx_deserialize($xml));
?>
Expected result:
----------------
NULL
Actual result:
--------------
$~ php7 --ini
Configuration File (php.ini) Path: /opt/php7/lib
Loaded Configuration File: (none)
Scan for additional .ini files in: (none)
Additional .ini files parsed: (none)
$~ php7 -v
PHP 7.2.0-dev (cli) (built: Sep 26 2016 15:29:49) ( NTS DEBUG )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.1.0-dev, Copyright (c) 1998-2016 Zend Technologies
$~ php7 wddx.php
NULL
[Mon Sep 26 15:43:39 2016] Script: '/opt/php7/bin/wddx.php'
/home/vps/git/php-src/ext/wddx/wddx.c(796) : Freeing 0x00007f410d200000
(8388609 bytes), script=/opt/php7/bin/wddx.php
=== Total 1 memory leaks detected ===
--
Edit bug report at https://bugs.php.net/bug.php?id=73173&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73173&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73173&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73173&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=73173&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=73173&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=73173&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=73173&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=73173&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=73173&r=support
Expected behavior: https://bugs.php.net/fix.php?id=73173&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=73173&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=73173&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=73173&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73173&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=73173&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=73173&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=73173&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=73173&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=73173&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=73173&r=mysqlcfg